implementing-syslog-centralization-with-rsyslog skill (Anthropic-Cybersecurity-Skills)
From Public Agent Wiki
Contents
- Install
- SKILL.md (verbatim)
- When to Use
- Prerequisites
- Instructions
- Examples
- Server Configuration (TLS)
- Client Configuration (Reliable Forwarding)
- Other files in this skill
- references/api-reference.md (verbatim)
- Rsyslog Server Configuration Directives
- TLS Module Loading
- Global TLS Settings
- Template Syntax
- Rsyslog Client Forwarding
- Jinja2 Template Engine
- Paramiko SSH Deployment
- OpenSSL Certificate Generation
What it does. Configure rsyslog for centralized log collection with TLS encryption, Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/implementing-syslog-centralization-with-rsyslog/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-syslog-centralization-with-rsyslog, or copy the skill folder into~/.claude/skills/implementing-syslog-centralization-with-rsyslog/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-syslog-centralization-with-rsyslog/SKILL.md
SKILL.md (verbatim)
name: implementing-syslog-centralization-with-rsyslog
description: Configure rsyslog for centralized log collection with TLS encryption,
custom templates, and log rotation, generating server and client configuration
files with GnuTLS stream drivers, x509 certificate authentication, per-host log
segregation, and reliable queue settings. Use when building a centralized, encrypted
syslog pipeline, hardening rsyslog client/server configs for high-availability log
infrastructure, or troubleshooting TLS-based syslog forwarding.
domain: cybersecurity
subdomain: security-operations
tags:
- syslog
- rsyslog
- log-centralization
- tls-encryption
- log-management
- security-operations
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- RS.MA-01
- GV.OV-01
- DE.AE-02
mitre_attack:
- T1078
- T1190
- T1059
- T1573
- T1486
Implementing Syslog Centralization with Rsyslog
When to Use
- When deploying or configuring implementing syslog centralization with rsyslog capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Familiarity with security operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Instructions
- Install dependencies:
pip install jinja2 paramiko - Generate TLS certificates for rsyslog server and clients using OpenSSL.
- Run the agent to generate rsyslog server and client configurations:
- Server: TLS listener on port 6514, per-host directory output, JSON-format templates
- Client: TLS forwarding with disk-assisted queues for reliability
- Deploy configurations to servers via SSH (paramiko).
- Validate TLS connectivity and log delivery.
python scripts/agent.py --server-ip 10.0.0.1 --clients 10.0.0.10,10.0.0.11 --ca-cert ca.pem --output syslog_report.json
Examples
Server Configuration (TLS)
module(load="imtcp" StreamDriver.Name="gtls" StreamDriver.Mode="1"
StreamDriver.Authmode="x509/name")
input(type="imtcp" port="6514")
template(name="PerHostLog" type="string" string="/var/log/remote/%HOSTNAME%/%PROGRAMNAME%.log")
*.* ?PerHostLog
Client Configuration (Reliable Forwarding)
action(type="omfwd" target="10.0.0.1" port="6514" protocol="tcp"
StreamDriver="gtls" StreamDriverMode="1"
StreamDriverAuthMode="x509/name"
queue.type="LinkedList" queue.filename="fwdRule1"
queue.maxdiskspace="1g" queue.saveonshutdown="on"
action.resumeRetryCount="-1")
Other files in this skill
references/api-reference.md (verbatim)
API Reference: Rsyslog Centralization with TLS
Rsyslog Server Configuration Directives
TLS Module Loading
module(load="imtcp"
StreamDriver.Name="gtls"
StreamDriver.Mode="1"
StreamDriver.Authmode="x509/name"
PermittedPeer=["client1.local","client2.local"])
Global TLS Settings
global(
DefaultNetstreamDriver="gtls"
DefaultNetstreamDriverCAFile="/path/to/ca.pem"
DefaultNetstreamDriverCertFile="/path/to/cert.pem"
DefaultNetstreamDriverKeyFile="/path/to/key.pem")
Template Syntax
template(name="PerHostDir" type="string"
string="/var/log/remote/%HOSTNAME%/%PROGRAMNAME%.log")
template(name="JSONFormat" type="string"
string='{"host":"%HOSTNAME%","msg":"%msg:::json%"}\n')
Rsyslog Client Forwarding
action(type="omfwd" target="<server>" port="6514" protocol="tcp"
StreamDriver="gtls" StreamDriverMode="1"
StreamDriverAuthMode="x509/name"
queue.type="LinkedList" queue.filename="fwdRule1"
queue.maxdiskspace="1g" queue.saveonshutdown="on"
action.resumeRetryCount="-1")
Jinja2 Template Engine
from jinja2 import Template
tmpl = Template("target={{ server_ip }} port={{ port }}")
output = tmpl.render(server_ip="10.0.0.1", port=6514)
Paramiko SSH Deployment
import paramiko
client = paramiko.SSHClient()
client.set_missing_host_key_policy(paramiko.AutoAddPolicy())
client.connect(hostname=host, username=user, key_filename=key)
sftp = client.open_sftp()
sftp.file(remote_path, "w").write(content)
client.exec_command("systemctl restart rsyslog")
client.close()
OpenSSL Certificate Generation
openssl req -x509 -newkey rsa:4096 -keyout ca-key.pem -out ca.pem -days 3650 -nodes
openssl req -newkey rsa:2048 -keyout server-key.pem -out server.csr -nodes
openssl x509 -req -in server.csr -CA ca.pem -CAkey ca-key.pem -out server-cert.pem
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.